Specific VPN user to exclude from session recording

Hi,

I have SPP and SPS versions 8.0.0. We are only using RDP.

In RDP connection policies, I have one policy which is the default one - safeguard_default.

All sessions are recorded.

I have a use case which I need to exclude one specific user from recording,

I understand from reading in this forum that I can easily do that by adding a configuration to channel policy, but I have a different problem

According to policy I present a banner to users that their sessions is being recorded and they click OK in order to continue the session, this option is configured of course under settings, and there is no option there to exclude a user from showing this,

I see that I can create a different RDP connection policy which will listen on a different port, and there I can also get rid of the banner, but the destinations that I need to allow for this user are also used by different users, and I don't want to exclude them from recording or from showing the banner.

Configuring a specific source IP address is also not an option, because this user is a VPN user who wont have a static IP address.

Do I have any other option?

  • Hello Shauls,

    if i understand you correctly you have the following option.

    on SPS:

    - Create new Connection Policy 

        - Set different port then default RDP policy

        - Create new RDP Settings without  banner

        - Create new RDP Chanel policy but untick option to record audit trail for each channel

        - in RDP connection enable "Share connection policy with SPP"

        - Place this Connection policy above the default RDP policy

    on SPP:

        - Create new Entitlement for user

        - Create new Access Request Policy

        - In security tab of Access Request Policy select "SPS Connection Policy" that you just created on SPS 

    Set other settings as you like.

    I think that should do it. I tested this in my environment and it works.

    This setup works like this:

        -   Other users connect same as before. They see the banner and their session is recorded.

        -   Special VPN user does not see the banner and his session is not recorded. 

    Best regards,

    Darko